295 karma · joined December 26, 2018
Because you cannot fix humans, technology is the most effective approach.
I am sorry to hear you had such a raw experience. Maybe you were dealing with pretty clueless engineers, since most do realize a buffer overflow should be treated exploitable unless proven otherwise. I've had better experience trying to argue the cost of fix -- it being pretty low was incentive enough for engineering to fix it.
That said, I am worried evilsocket may not be taken seriously next time he finds a vulnerability with CVSS 9.9. To some extent I am surprised by his argument on not knowing CVSS scoring rubrik. There may have been language barrier at play as well, leading to some of his sentences coming across as more abrasive than they should have been.
(I am disappointed about this oft thrown around comparison, since my city reduced one lane on several major roads and created bike paths. Sadly, we now have major traffic jams and hardly any utilization of the bike path. Turns out someone on the city council wanted to turn it into Denmark)
(And I am asking this in a friendly tone, as a genuinely curious question, and not a combative one. These nuances get lost, so putting them down in words). Thanks.
Thanks for these recommendations. :)